Sophos

W32/MemServ-A

Aliases
  • Worm.Win32.Agent.ct
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 17 November 2007 05:23:00 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/MemServ-A is a worm for the Windows platform.

W32/MemServ-A includes functionality to send notification messages to remote locations.

When first run W32/MemServ-A copies itself to <Windows>\svchost.exe.

W32/MemServ-A attempts to periodically copy itself to removable drives, including floppy drives and USB keys. The worm will attempt to create the hidden file autorun.inf on the removeable drive and copy itself to a hidden file in the same location with the filename Setup.exe. The file autorun.inf is designed to start the worm once the removable drive is connected to a uninfected computer.

The following registry entry is set in order to run W32/MemServ-A on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Windows>\svchost.exe

W32/MemServ-A continuously listens on port 7553 for incoming TCP connections.

W32/MemServ-A logs keystrokes and launched applications on the victim computer. This information is stored in the file <System>logfile.txt.


RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer